cbcvebase.
CVE-2025-38342
published 2025-07-10

CVE-2025-38342: In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args()…

high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
In the Linux kernel, the following vulnerability has been resolved: software node: Correct a OOB check in software_node_get_reference_args() software_node_get_reference_args() wants to get @index-th element, so the property value requires at least '(index + 1) * sizeof(*ref)' bytes but that can not be guaranteed by current OOB check, and may cause OOB for malformed property. Fix by using as OOB check '((index + 1) * sizeof(*ref) > prop->length)'.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 142acd739eb6f08c148a96ae8309256f1422ff4b142acd739eb6f08c148a96ae8309256f1422ff4b
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 56ce76e8d406cc72b89aee7931df5cf3f18db49d56ce76e8d406cc72b89aee7931df5cf3f18db49d
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 9324127b07dde8529222dc19233aa57ec810856c9324127b07dde8529222dc19233aa57ec810856c
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < f9397cf7bfb680799fb8c7f717c8f756384c3280f9397cf7bfb680799fb8c7f717c8f756384c3280
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 4b3383110b6df48e0ba5936af2cb68d5eb6bd43b4b3383110b6df48e0ba5936af2cb68d5eb6bd43b
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 7af18e42bdefe1dba5bcb32555a4d524fd5049397af18e42bdefe1dba5bcb32555a4d524fd504939
linuxlinux>= 59abd83672f70cac4b6bf9b237506c5bc6837606 < 31e4e12e0e9609850cefd4b2e1adf782f56337d631e4e12e0e9609850cefd4b2e1adf782f56337d6
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.0 < 5.10.2395.10.239
linuxlinux_kernel>= 5.11 < 5.15.1865.15.186
linuxlinux_kernel>= 5.16 < 6.1.1426.1.142
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.2 < 6.6.956.6.95
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH